logo

MirrorFace updates toolset, expands targeting to Europe

ID: a7cb5958-48d9-53b0-8d98-6383f4b66cad

STIX ID: report--a7cb5958-48d9-53b0-8d98-6383f4b66cad

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
85/100

Date Published: 2025-03-18

Date Updated: 2026-05-01

...
...

ESET reports that the China-aligned MirrorFace APT launched Operation AkaiRyū, a spearphishing campaign using World Expo 2025-themed lures to target a Central European diplomatic institute, leveraging legitimate applications to install malware and reportedly reviving the Anel backdoor; this marks the group's first observed attempt to infiltrate an organization in Europe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.